Impact
The vulnerability allows an authenticated local user to delete files arbitrarily with elevated privileges, effectively enabling a privilege‑escalation attack that can destroy critical data. The flaw is a boundary‑violating path traversal weakness, mapped to CWE‑59. Consequently, attackers can compromise data integrity and potentially affect system integrity if essential files are removed.
Affected Systems
Lenovo Dock Manager, as shipped on Lenovo workstations and docking stations. No specific affected version range is listed; administrators should verify the currently installed version of the Dock Manager component.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS information is not available and the vulnerability is not in CISA KEV, implying no documented widespread exploitation. The attack vector is inferred to be a local authenticated user with the ability to elevate privileges; therefore exploitation is largely confined to the local host. The risk hinges on the ability to delete files that may be critical to system operation or user data, potentially leading to denial of service or facilitating further compromise. No public exploits are known, so the threat is primarily theoretical at this time.
OpenCVE Enrichment